{"type":"post","stable_id":"post:agent-security-moves-outside-the-model","slug":"agent-security-moves-outside-the-model","title":"Agent Security Moves Outside the Model","description":"As agent autonomy grows, security is moving to external boundaries: sandbox containment, network observation, protocol-aware policy, constrained credentials, and independent receipts.","retrieval_nugget":"Incidents and defensive controls across several layers point to the same architecture: safety cannot depend on a compliant prompt when action can be contained and audited outside the model.","published_at":"2026-08-14","updated_at":"2026-08-15","record_date":"2026-08-14","date_kind":"discovered_at","topics":["security","agents","architecture"],"entities":["Cloudflare","AI-agent security"],"source_urls":["https://www.axios.com/2026/08/11/open-source-security-ai-agent-reporting","https://www.reuters.com/legal/litigation/chinese-startup-moonshots-ai-model-breaks-out-testing-environment-researchers-2026-08-07","https://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan","https://blog.cloudflare.com/mcp-security-updates"],"source_format":"article","editorial_timing":{"lane":"regular_hourly","scheduled_at":"2026-08-22T09:00:00+03:00","real_news_delta":"owner-selected cross-source synthesis"},"origin":{"basket_id":"5854f7b2-5954-4d2a-8997-81596a49da74","basket_revision":1,"target_kind":"synthesis","target_id":"b7cddbce-3413-43c9-a43c-c07d376876ed","owner_selection":"46","route":"hermes"},"visual_decision":{"outcome":"generate_explanatory_diagram","status":"included","reason_code":"architecture_or_boundary","explanatory_value":"security controls surround the agent at credential, sandbox, network, protocol, approval, and receipt boundaries","text_only_limitation":"The thesis is spatial: independent controls exist outside model reasoning. A layered boundary diagram prevents those controls from collapsing into a vague safety checklist.","owner_reviewed":true,"reviewed_by":"owner-and-codex"},"schema_version":"newruntime-agent-readable-v0.2","status":"published","visuals":[{"role":"hero","src":"/images/drip/agent-security-moves-outside-the-model/agent-security-moves-outside-the-model.webp","alt":"New Runtime whiteboard diagram explaining agent security moves outside the model.","caption":"New Runtime synthesis from axios.com."}],"routes":{"html":"https://newruntime.com/posts/agent-security-moves-outside-the-model/","markdown":"https://newruntime.com/posts/agent-security-moves-outside-the-model.md","json":"https://newruntime.com/posts/agent-security-moves-outside-the-model.json"}}
